Software in scope, plus Article 12 ยท Regulation (EU) 2024/2847

Do AI products fall under the EU CRA?

Verified against the Official Journal text on

Depends on what you ship; Article 12 links the AI Act (Art. 3(1), Art. 12)

An AI product is software, so it is in scope of the CRA on the same terms as any other product with digital elements: a downloadable or installable AI tool supplied to EU users in the course of business is caught, while a purely hosted service with nothing installed follows the same online-service line as other SaaS. On top of that, Article 12 links the two regimes. Where a product with digital elements in CRA scope is a high-risk AI system under the AI Act, meeting the CRA essential requirements deems it to comply with the AI Act's cybersecurity requirement, and the AI Act's conformity procedure generally applies, with a carve-out preserving the CRA route for important and critical products.

Basis: Art. 3(1), Art. 12

Judgment call: Whether you ship a downloadable model, weights, or tools (a product) or offer only a hosted model API (an online service) follows the same installable-component line as other SaaS, and is a judgment on what the customer actually receives.

An AI product is a software product Art. 3(1), Recital 12

The CRA does not carve AI out. A product with digital elements is software or hardware plus its remote data processing solutions, and an AI tool is software. A downloadable or installable AI application, model runtime, or agent supplied to EU users in the course of business is in scope like any other software product.

The hosted-versus-downloadable distinction matters here as it does for SaaS. A purely browser-based or API-only AI service with nothing installed is closer to an online service, while shipping downloadable weights, a desktop client, or tools puts a product in scope. Assess what the customer actually receives.

Judgment call: The line between a hosted AI service and a downloadable AI product turns on what is installed, the same functional judgment the CRA applies to other online services.

Article 12: how the CRA meets the AI Act Art. 12(1), Art. 12(2)

Article 12 addresses products with digital elements that fall within CRA scope and are classified as high-risk AI systems under Article 6 of Regulation (EU) 2024/1689 (the AI Act). Such products are deemed to comply with the cybersecurity requirements in Article 15 of the AI Act where they fulfil the essential requirements in Part I of Annex I, their processes comply with Part II of Annex I, and the level of protection required under Article 15 of the AI Act is demonstrated in the EU declaration of conformity issued under the CRA.

For those products and requirements, the conformity assessment procedure in Article 43 of the AI Act applies. Notified bodies competent under the AI Act are also competent to check conformity with Annex I of the CRA, provided they meet the CRA notification requirements.

The carve-out for important and critical AI products Art. 12(3), Art. 12(4)

Article 12 includes a derogation. Important products under Annex III that are subject to the stricter conformity procedures, and critical products under Annex IV that need a European cybersecurity certificate or the stricter procedures, which are also high-risk AI systems to which the AI Act's internal-control conformity route applies, are instead subject to the CRA conformity procedures for the essential cybersecurity requirements.

In short, the AI Act route is the default for high-risk AI systems that are in CRA scope, but the CRA route is preserved for the important and critical categories so the level of assurance is not reduced. Manufacturers of these products may also take part in the AI regulatory sandboxes under the AI Act.

Obligations and the dates Art. 13, Art. 14, Art. 71(2)

For an in-scope AI product you still meet the CRA essential cybersecurity requirements, handle vulnerabilities (including a coordinated vulnerability disclosure policy), draw up technical documentation, and complete the applicable conformity route (the AI Act procedure, or the CRA procedure where the carve-out applies). Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.

What you must do

  • Design, develop, and produce the AI product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Complete the applicable conformity route: the AI Act procedure for high-risk AI systems, or the CRA procedure where the important or critical carve-out applies. (Art. 12(2), Art. 12(3))
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
For an in-scope AI product, reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
For an in-scope AI product, the full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

We only offer a hosted model API. Are we in scope of the CRA?

A purely hosted service with nothing installed follows the same online-service line as other SaaS, which sits under NIS2. This changes if you ship a downloadable component, such as weights, a desktop client, or tools, which is then a product in scope. (Art. 3(1), Recital 12)

Our AI product is a high-risk AI system under the AI Act. Do both regimes apply?

Article 12 connects them. Meeting the CRA essential requirements deems the product to comply with the AI Act's cybersecurity requirement, and the AI Act's conformity procedure generally applies, with a carve-out that keeps the CRA route for important and critical products. (Art. 12(1), Art. 12(2), Art. 12(3))

Does Article 12 change our vulnerability handling and reporting?

No. Article 12 addresses how the essential requirements and conformity assessment interact with the AI Act. The CRA vulnerability handling and reporting duties still apply to an in-scope AI product on the usual timeline. (Art. 12, Art. 13, Art. 14)

Check where your AI product lands

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether your AI product is in scope, what you ship, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.